Kernel: gsm multiplexing race condition leads to privilege escalation
Published Dec 21, 2023
7.0
HIGHCVSS 3.1
EPSS 0.73%
Description
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.
Affected products
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 9 | affected |
Configuration 1
- < 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
Configuration 2
- 39
Configuration 3
- 8.0
- 9.0
No data.
RHOL-5.7-RHEL-8
openshift-logging/cluster-logging-operator-bundle:v5.7.13-16
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/cluster-logging-rhel8-operator:v5.7.13-7
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/elasticsearch-operator-bundle:v5.7.13-19
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/elasticsearch-proxy-rhel8:v1.0.0-480
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/elasticsearch-rhel8-operator:v5.7.13-9
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/elasticsearch6-rhel8:v6.8.1-408
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/eventrouter-rhel8:v0.4.0-248
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/fluentd-rhel8:v1.14.6-215
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/kibana6-rhel8:v6.8.1-431
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/log-file-metric-exporter-rhel8:v1.1.0-228
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/logging-curator5-rhel8:v5.8.1-471
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/logging-loki-rhel8:v2.9.6-15
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/logging-view-plugin-rhel8:v5.7.13-3
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/loki-operator-bundle:v5.7.13-27
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/loki-rhel8-operator:v5.7.13-12
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/lokistack-gateway-rhel8:v0.1.0-527
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/opa-openshift-rhel8:v0.1.0-225
Fixed · RHSA-2024:2093
RHOL-5.7-RHEL-8
openshift-logging/vector-rhel8:v0.28.1-57
Fixed · RHSA-2024:2093
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.24.1.el8_9
Fixed · RHSA-2024:1607
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.24.1.rt7.326.el8_9
Fixed · RHSA-2024:1614
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2024:1612
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.136.1.el8_2
Fixed · RHSA-2024:4577
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.134.1.el8_4
Fixed · RHSA-2024:4731
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-0:4.18.0-305.134.1.el8_4
Fixed · RHSA-2024:4731
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-rt-0:4.18.0-305.134.1.rt7.210.el8_4
Fixed · RHSA-2024:4729
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kernel-0:4.18.0-305.134.1.el8_4
Fixed · RHSA-2024:4731
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2024:4970
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.93.1.el8_6
Fixed · RHSA-2024:0930
Red Hat Enterprise Linux 8.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2024:0937
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.55.1.el8_8
Fixed · RHSA-2024:2621
Red Hat Enterprise Linux 8.8 Extended Update Support
kpatch-patch
Fixed · RHSA-2024:2697
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.13.1.el9_4
Fixed · RHSA-2024:2394
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.13.1.el9_4
Fixed · RHSA-2024:2394
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.93.2.el9_0
Fixed · RHSA-2024:1250
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.93.1.rt21.165.el9_0
Fixed · RHSA-2024:1306
Red Hat Enterprise Linux 9.0 Extended Update Support
kpatch-patch
Fixed · RHSA-2024:1253
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.55.1.el9_2
Fixed · RHSA-2024:1018
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.55.1.rt14.340.el9_2
Fixed · RHSA-2024:1019
Red Hat Enterprise Linux 9.2 Extended Update Support
kpatch-patch
Fixed · RHSA-2024:1055
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.93.1.el8_6
Fixed · RHSA-2024:0930
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHOL-5.7-RHEL-8 | openshift-logging/cluster-logging-operator-bundle:v5.7.13-16 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/cluster-logging-rhel8-operator:v5.7.13-7 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/elasticsearch-operator-bundle:v5.7.13-19 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/elasticsearch-proxy-rhel8:v1.0.0-480 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/elasticsearch-rhel8-operator:v5.7.13-9 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/elasticsearch6-rhel8:v6.8.1-408 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/eventrouter-rhel8:v0.4.0-248 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/fluentd-rhel8:v1.14.6-215 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/kibana6-rhel8:v6.8.1-431 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/log-file-metric-exporter-rhel8:v1.1.0-228 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/logging-curator5-rhel8:v5.8.1-471 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/logging-loki-rhel8:v2.9.6-15 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/logging-view-plugin-rhel8:v5.7.13-3 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/loki-operator-bundle:v5.7.13-27 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/loki-rhel8-operator:v5.7.13-12 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/lokistack-gateway-rhel8:v0.1.0-527 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/opa-openshift-rhel8:v0.1.0-225 | Fixed | RHSA-2024:2093 |
| RHOL-5.7-RHEL-8 | openshift-logging/vector-rhel8:v0.28.1-57 | Fixed | RHSA-2024:2093 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.24.1.el8_9 | Fixed | RHSA-2024:1607 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.24.1.rt7.326.el8_9 | Fixed | RHSA-2024:1614 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2024:1612 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.136.1.el8_2 | Fixed | RHSA-2024:4577 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.134.1.el8_4 | Fixed | RHSA-2024:4731 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-0:4.18.0-305.134.1.el8_4 | Fixed | RHSA-2024:4731 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-rt-0:4.18.0-305.134.1.rt7.210.el8_4 | Fixed | RHSA-2024:4729 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kernel-0:4.18.0-305.134.1.el8_4 | Fixed | RHSA-2024:4731 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2024:4970 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.93.1.el8_6 | Fixed | RHSA-2024:0930 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2024:0937 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.55.1.el8_8 | Fixed | RHSA-2024:2621 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kpatch-patch | Fixed | RHSA-2024:2697 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.13.1.el9_4 | Fixed | RHSA-2024:2394 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.13.1.el9_4 | Fixed | RHSA-2024:2394 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.93.2.el9_0 | Fixed | RHSA-2024:1250 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.93.1.rt21.165.el9_0 | Fixed | RHSA-2024:1306 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kpatch-patch | Fixed | RHSA-2024:1253 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.55.1.el9_2 | Fixed | RHSA-2024:1018 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.55.1.rt14.340.el9_2 | Fixed | RHSA-2024:1019 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kpatch-patch | Fixed | RHSA-2024:1055 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.93.1.el8_6 | Fixed | RHSA-2024:0930 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
This flaw can be mitigated by preventing the affected `n_gsm` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.
Red Hat statement
This vulnerability is critical because it can be exploited to escalate privileges, directly threatening system security. Despite requiring local access and having a high attack complexity, the potential to severely impact confidentiality, integrity, and availability justifies its "Important" rating.
Red Hat mitigation
This flaw can be mitigated by preventing the affected `n_gsm` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.
References (34)
- http://www.openwall.com/lists/oss-security/2024/04/10/18
- http://www.openwall.com/lists/oss-security/2024/04/10/21
- http://www.openwall.com/lists/oss-security/2024/04/11/7
- http://www.openwall.com/lists/oss-security/2024/04/11/9
- http://www.openwall.com/lists/oss-security/2024/04/12/1
- http://www.openwall.com/lists/oss-security/2024/04/12/2
- http://www.openwall.com/lists/oss-security/2024/04/16/2
- http://www.openwall.com/lists/oss-security/2024/04/17/1
- https://access.redhat.com/errata/RHSA-2024:0930 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0937 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1018 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1019 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1055 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1250 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1253 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1306 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1607 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1612 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1614 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2093 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2394 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2621 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2697 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4577 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4729 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4731 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4970 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6546 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2255498 issue-trackingx_refsource_REDHATIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58776 Advisory
- https://github.com/torvalds/linux/commit/3c4f8333b582487a2d1e02171f1465531cde53e3 Patch
- https://nvd.nist.gov/vuln/detail/CVE-2023-6546
- https://www.cve.org/CVERecord?id=CVE-2023-6546
- https://www.zerodayinitiative.com/advisories/ZDI-CAN-20527
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data